ECB warns AI risks force banks to rethink DORA testing

Frank Elderson

European banks may need to fundamentally rethink their approach to software testing, threat-led penetration testing and digital resilience as artificial intelligence rapidly transforms the cyber threat landscape, according to the European Central Bank.

Speaking at the recent Goldman Sachs European Financials Conference in Zurich, Frank Elderson, Member of the Executive Board of the ECB and Vice-Chair of the Supervisory Board of the ECB, warned that advanced AI models are dramatically changing the economics of cyber risk and shrinking the time available for banks to detect and remediate vulnerabilities.

“The direction of travel is unmistakable: the speed, scale and accessibility of advanced cyber capabilities are increasing, and the time available to defenders is shrinking,” Elderson told delegates.

For software testing and resilience teams in banking, the message is clear: traditional testing cycles and periodic security reviews are increasingly inadequate in an environment where AI-enabled attackers can discover and exploit vulnerabilities at unprecedented speed.

“Banks therefore need to prepare more quickly, more effectively and more consistently across the sector,” Elderson stated.

“In musical terms, andante may have previously been good enough, but now we need to move to presto.”

TLPT under DORA

The remarks come as banks across Europe continue implementing the Digital Operational Resilience Act (DORA), which has significantly expanded regulatory expectations around ICT testing, operational resilience and threat-led penetration testing (TLPT).

According to Elderson, DORA “provides a regulatory framework that requires banks to foster a culture of continuous improvement in IT and cyber risk management” and has strengthened oversight of critical third-party providers, including cloud firms.

Crucially for testing teams, he noted that DORA “gave supervisors the task of testing whether a financial institution can detect, respond to and recover from sophisticated attacks that mirror real-world threats, thereby providing a more systemic and enforceable framework for resilience.”

That emphasis on realistic testing aligns closely with the ECB’s own push to embed its Threat Intelligence-Based Ethical Red Teaming framework, TIBER-EU, into the DORA regime.

The ECB headquarters in Frankfurt, Germany
ECB’s HQ In Frankfurt

Earlier this year, the ECB formally positioned TIBER-EU as the supervisory model for DORA’s mandatory threat-led penetration testing requirements, shifting resilience assessments away from isolated technical tests towards intelligence-led exercises designed to replicate genuine attacks.

For QA and software testing functions, this means that resilience testing increasingly extends beyond application security and vulnerability scanning into end-to-end assessments of detection, response, recovery and governance.

As QA Financial previously reported, TLPT under DORA requires certain financial institutions to undergo advanced testing exercises that simulate sophisticated adversaries and validate operational resilience under realistic conditions. Findings feed directly into remediation programmes, development pipelines and broader resilience strategies.

The urgency of that work is increasing because of AI, according to Elderson.

“Our current understanding is that tools of this kind are not simply another incremental improvement; they are a structural shift in the economics of cyber risk,” he said.

The ECB official highlighted the emergence of advanced cyber-capable AI models that can identify and exploit vulnerabilities, combine seemingly minor weaknesses into larger attacks and reverse-engineer patches into new exploits.

“Cyberattacks that previously required significant expertise, time and resources may in future be achieved more quickly, at scale, and by a much broader set of potentially malicious actors,” he warned.

Testing requirements

The comments echo growing concerns among resilience specialists that DORA’s testing requirements may need to evolve continuously as AI compresses the window between vulnerability disclosure and exploitation.

For banks, this has profound implications for patch management, regression testing and production resilience. Systems once regarded as adequately protected may no longer be resilient against increasingly automated and intelligent adversaries.

“Frontier AI models are changing the cyber threat landscape,” Elderson said. “They are lowering barriers for attackers, increasing the speed of exploitation and exposing weaknesses that were too often tolerated for too long.”

The ECB’s concerns extend beyond individual institutions to systemic dependencies across the financial sector.

“Scenarios that were once considered tail risks may become more likely, such as vulnerabilities in a single, widely used infrastructure quickly escalating into disruption across an entire sector, with knock-on effects on banks’ ability to operate,” he stressed.


“Banks’ preparedness is still weak. Frontier AI models are lowering barriers, exposing weaknesses that were too often tolerated for too long.”

– Frank Elderson

Such concerns reinforce one of DORA’s central themes: resilience is no longer simply about preventing incidents but about maintaining critical services during disruption and recovering rapidly when systems fail.

The ECB’s own cyber resilience stress test of 109 banks in 2024 demonstrated progress, with almost three-quarters of identified findings subsequently addressed. But Elderson suggested significant work remains.

“Some banks’ preparedness is still weak,” he said.

As a result, the ECB plans to increase supervisory pressure. Elderson revealed that the Single Supervisory Mechanism will shortly send a “dear CEO letter” asking banks “to take proactive measures to ensure the continued robustness and security of their systems in the face of these transformative challenges”.

“Our aim is straightforward: to ensure that banks take the necessary steps now, before these technologies are more widely used by threat actors,” he said.

For QA and software testing teams, the speech is another indication that resilience testing is moving to the centre of supervisory expectations. DORA’s emphasis on continuous testing, threat-led penetration testing and recovery validation increasingly positions testing functions as a critical line of defence against AI-enabled threats.

“This is not about creating a sense of alarm, but rather a sense of urgency,” Elderson summarised.

“Because we cannot afford to be complacent. Our message as supervisors is simple: act early, invest decisively now, and do not wait for the next incident to reveal where your vulnerabilities lie,” he concluded.


16 SEPTEMBER IN LONDON

REGISTER TODAY – SIMPLY CLICK HERE


Why not become a QA Financial subscriber?

It’s entirely FREE

* Receive our weekly newsletter every Wednesday * Get priority invitations to our Forum events *

SIGN UP HERE TODAY


QA FINANCIAL PODCASTS

CLICK HERE TO LISTEN TO OUR EXCLUSIVE CONVERSATIONS


REGULATION & COMPLIANCE

Looking for more news on regulations and compliance requirements driving developments in software quality engineering at financial firms? Visit our dedicated Regulation & Compliance page here.


READ MORE


WATCH NOW